3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-44158
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function via set_device_name.

CVE-2022-25298
sprinfall/webcc General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

This affects the package sprinfall/webcc before 0.3.0. It is possible to traverse directories to fetch arbitrary files from the server.

CVE-2022-4379
Linux kernel General
7.5
HIGH
EPSS
0.4%
2022 CWE-416 2 PoCs

A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial

CVE-2022-42277
NVIDIA DGX servers General
7.5
HIGH
EPSS
0.0%
2022 CWE-288 1 PoC

NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

CVE-2022-25888
opcua General
7.5
HIGH
EPSS
0.5%
2022 1 PoC

The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

CVE-2022-25851
jpeg-js General
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.

CVE-2022-26303
OAS Platform General
7.5
HIGH
EPSS
0.3%
2022 CWE-306 1 PoC

An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of an OAS user account. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-34393
BIOS General
7.5
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-47116
Software Genérico General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the SYSPS parameter at /goform/SysToolChangePwd.

CVE-2022-45269
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
27.4%
2022 0 PoCs

A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.

CVE-2022-2591
FLEX-1085 General
7.5
HIGH
EPSS
3.8%
2022 CWE-404 1 PoC

A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the file /sistema/flash/reboot. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-25836
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure Connections Passkey Pairing with the pairing Responder and brute forces the Passkey entered by the user into the Initiator. The MITM attacker can use the identified Passkey value to complete authentication with the Responder via Bluetooth pairing method confusion.

CVE-2022-25304
opcua General
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

CVE-2022-41999
OpenImageIO General
7.5
HIGH
EPSS
0.3%
2022 CWE-476 1 PoC

A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-23082
CureKit General
7.5
HIGH
EPSS
0.6%
2022 CWE-22 2 PoCs

In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal.

CVE-2022-42733
syngo Dynamics General
7.5
HIGH
EPSS
0.3%
2022 CWE-73 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool.

CVE-2022-44216
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password.

CVE-2022-39812
Software Genérico General
7.5
HIGH
EPSS
1.2%
2022 1 PoC

Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to an arbitrary path. An attacker can change the uploadDir parameter in a POST request (not possible using the GUI) to an arbitrary directory. Because the application does not check in which directory a file will be uploaded, an attacker can perform a variety of attacks that can result in unauthorized access to the server.

CVE-2022-44167
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Tenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer.

CVE-2022-47717
Software Genérico General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).